libsamplerate Buffer Overflow Vulnerability
BID:32090
Info
libsamplerate Buffer Overflow Vulnerability
| Bugtraq ID: | 32090 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-5008 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2008 12:00AM |
| Updated: | Dec 05 2008 06:01PM |
| Credit: | Russell O'Connor |
| Vulnerable: |
Pardus Linux 2008 0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 libsamplerate libsamplerate 0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
libsamplerate Buffer Overflow Vulnerability
The 'libsamplerate' program (aka Secret Rabbit Code) is prone to a buffer-overflow vulnerability because of insufficient boundary checks.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted files with an application that uses the affected library.
Successful exploits may allow attackers to execute arbitrary code within the context of an affected application. Failed exploit attempts will likely result in a denial of service.
The 'libsamplerate' program (aka Secret Rabbit Code) is prone to a buffer-overflow vulnerability because of insufficient boundary checks.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted files with an application that uses the affected library.
Successful exploits may allow attackers to execute arbitrary code within the context of an affected application. Failed exploit attempts will likely result in a denial of service.
Exploit / POC
libsamplerate Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libsamplerate Buffer Overflow Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.1
Mandriva Linux Mandrake 2008.0
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva lib64samplerate-devel-0.1.3-0.pre6.3.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64samplerate0-0.1.3-0.pre6.3.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.1.3-0.pre6.3.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva lib64samplerate-devel-0.1.3-0.pre6.3.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64samplerate0-0.1.3-0.pre6.3.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.1.3-0.pre6.3.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva libsamplerate-devel-0.1.3-0.pre6.3.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.1.3-0.pre6.3.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-0.1.3-0.pre6.3.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva libsamplerate-devel-0.1.3-0.pre6.3.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.1.3-0.pre6.3.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-0.1.3-0.pre6.3.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva libsamplerate-progs-0.1.2-1.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-0.1.2-1.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-devel-0.1.2-1.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva lib64samplerate0-0.0.15-2.1.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64samplerate0-devel-0.0.15-2.1.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.0.15-2.1.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0
-
Mandriva libsamplerate-progs-0.0.15-2.1.C30mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-0.0.15-2.1.C30mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate0-devel-0.0.15-2.1.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva lib64samplerate0-0.1.2-1.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64samplerate0-devel-0.1.2-1.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva libsamplerate-progs-0.1.2-1.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
libsamplerate Buffer Overflow Vulnerability
References:
References:
- libsamplerate Changelog (libsamplerate)
- libsamplerate Homepage (libsamplerate)